Privacy policy
Last updated: 11 August 2026
1. Who we are
AIDENTYA is a hotel AI-discovery service operated by StayKeasy Srl (the “data controller”). For any privacy request write to privacy@staykeasy.com.
2. What data we process
Account data: email address and authentication data used to create and secure your account.
Hotel data: the website URL you submit and the publicly available content published on that website, which we read to build a verified hotel profile.
Scan data: the guest queries we generate, the AI answers returned, the properties mentioned in them, your visibility metrics and your improvement actions.
Billing data: subscription status and identifiers. Card details are handled entirely by Stripe and never reach our servers.
We do not collect guest personal data and AIDENTYA is not a guest-facing booking system.
3. Why we process it and on what legal basis
To provide the service you requested — website analysis, AI discovery scans, dashboards, reports and the improvement plan (performance of a contract, Art. 6(1)(b) GDPR).
To bill subscriptions and meet accounting obligations (legal obligation, Art. 6(1)(c) GDPR).
To keep the product secure and improve it through aggregated, non-identifying usage statistics (legitimate interest, Art. 6(1)(f) GDPR).
To send optional product emails where you have opted in (consent, Art. 6(1)(a) GDPR).
4. Processors we rely on
Supabase (database, authentication, hosting infrastructure), Google (Gemini API with Google Search grounding, used to run discovery queries), Firecrawl (public website reading), and Stripe (payments). Each acts as a processor or independent controller under a data processing agreement. Some processing may occur outside the EEA under Standard Contractual Clauses.
The content of your discovery scans is not sold, shared with other hotels, or used to train third-party models by us.
5. Retention
Account and scan data are kept while your account is active and for up to 12 months after cancellation, so you can restore history. Billing records are kept for 10 years as required by Italian law. You can ask for deletion at any time.
6. Your rights
You may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest, by emailing privacy@staykeasy.com. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
7. Security
Data is encrypted in transit, access to production data is restricted, and database rows are protected by row-level security policies so that each account only reaches its own properties.